Cisco PIX 525 Spezifikationen Seite 205

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 466
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 204
5-29
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 5 Configuring Application Inspection (Fixup)
Multimedia Applications
TCP Stream
TCP streams are used with Netshow as follows:
1. Client makes a TCP connection to the server using the well-known port 1755.
2. Once a connection is established, the client sends an LVMConnectFunnel message to the server
confirming the use of TCP connection.
3. Server sends the stream in the already connected TCP port.
4. Netshow session ends by tearing down the TCP connection.
Real Time Streaming Protocol (RTSP)
You can use the fixup command to change the default port assignment for the Real Time Streaming
Protocol (RTSP). The command syntax is as follows.
fixup rtsp [port]
The fixup protocol rtsp command lets PIX Firewall pass RTSP packets. RTSP is used by RealAudio,
RealNetworks, Apple QuickTime 4, RealPlayer, and Cisco IP/TV connections. PIX
Firewall does not
support multicast RTSP.
If you are using Cisco IP/TV, use RTSP TCP port 554 and TCP 8554:
fixup protocol rtsp 554
fixup protocol rtsp 8554
The following restrictions apply to the fixup protocol rtsp command:
This PIX Firewall will not fix RTSP messages passing through UDP ports.
PIX Firewall does not support RealNetworks multicast mode (x-real-rdt/mcast).
PAT is not supported with the fixup protocol rtsp command.
PIX Firewall does not have the ability to recognize HTTP cloaking where RTSP messages are
hidden in the HTTP messages.
PIX Firewall cannot perform NAT on RTSP messages because the embedded IP addresses are
contained in the SDP files as part of HTTP or RTSP messages. Packets could be fragmented and
PIX
Firewall cannot perform NAT on fragmented packets.
With Cisco IP/TV, the number of NATs the PIX Firewall performs on the SDP part of the message
is proportional to the number of program listings in the Content Manager (each program listing can
have at least six embedded IP addresses).
You can configure NAT for Apple QuickTime 4 or RealPlayer. Cisco IP/TV only works with NAT
if the Viewer and Content Manager are on the outside network and the server is on the inside
network.
When using RealPlayer, it is important to properly configure transport mode. For the PIX Firewall,
add an access-list command statement from the server to the client or vice versa. For RealPlayer,
change transport mode by clicking Options>Preferences>Transport>RTSP Settings.
If using TCP mode on the RealPlayer, select the Use TCP to Connect to Server and Attempt to
use TCP for all content check boxes. On the PIX
Firewall, there is no need to configure the fixup.
If using UDP mode on the RealPlayer, select the Use TCP to Connect to Server and Attempt to
use UDP for static content check boxes. On the PIX
Firewall, add a fixup protocol rtsp port
command statement.
Seitenansicht 204
1 2 ... 200 201 202 203 204 205 206 207 208 209 210 ... 465 466

Kommentare zu diesen Handbüchern

Keine Kommentare